PT-2026-67744 · Kotaemon · Kotaemon
CVSS v3.1
9.8
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
kotaemon versions prior to 0.12.1
Description
An insecure deserialization issue exists in the 'check connection' endpoint. Unauthenticated attackers can instantiate arbitrary Python classes by providing crafted YAML or JSON input containing a
type field. By overriding the type field with the subprocess.check output() function and providing arbitrary arguments, an attacker can achieve remote code execution with the privileges of the application process.Recommendations
Update kotaemon to a version later than 0.12.0.
As a temporary mitigation, restrict access to the 'check connection' endpoint.
Exploit
Fix
RCE
Deserialization of Untrusted Data
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Kotaemon